As if ransomware weren't already causing enough problems on computers, we now discover that its developers are redirecting resources towards mobile devices. According to McAfee's mobile malware research division, "ElGato" is a ransomware designed to infect the Android operating system, with the ability to encrypt users' personal files, steal SMS messages, and of course, block access to the device.

ElGato: New Android Ransomware Steals SMS Messages
ElGato

Why Mobile Devices Are a Prime Target

It's no secret that mobile devices have become a very tempting target for malware developers. The average user often stores credentials for various services on their smartphone, and more than a few already make electronic payments via mobile. Imagine what an attacker could do with access to Facebook, Snapchat, Instagram, Dropbox, PayPal, Gmail, and other similar platforms. The user's "digital life" would descend into chaos, although there is a much more interesting and lucrative option: holding all those services hostage. Ransomware on computers has a certain preference for government agency terminals, hospitals, and schools, but if it moves onto mobile devices, the "rewards" could be even greater.

ElGato: New Android Ransomware Steals SMS Messages
This is the cat that researchers found in the code.

Meet ElGato

This brings us to a recent discovery by McAfee's mobile malware research division. The division found a ransomware sample with botnet capabilities that they named "ElGato" because they found the image of a cat in a window within its code. The most curious thing is that "ElGato" would serve as a kind of demo for the commercialization of kits that a criminal could deploy on the Web with basic knowledge. Another detail confirming its role as a demo is that all communication with the command and control center goes through HTTP, without any encryption. This allowed researchers to get a clearer idea of its attack types: encrypting data on the SD card, automatically sending and deleting SMS messages, and locking the screen.

ElGato: New Android Ransomware Steals SMS Messages
All connections, even the control panel, were without any protection. Just a demo, or the basis for something more dangerous...?

A Growing Threat

Although we are convinced that the "ElGato" adventure has come to an end (its main service runs on legitimate servers, and McAfee has already contacted the provider to get it removed from the Web), nothing prevents it from evolving into something much more dangerous. In other words, ElGato is a ransomware in development. As always, those Android users who use alternative stores or manually download APKs must ensure that the source of the files is reliable and "clean".

Official announcement: